Modern organizations are adopting new ways of measuring their level of security for compliance and justification of security investments. The highly interconnected environment has seen organizations generate lots of personal information and sensitive organizational data. Easiness in automation provided by open-source enterprise resource planning (ERP) software has accelerated its acceptability. The study aimed at developing a security measurement framework for open-source ERP software. The motivation was twofold: paradigm shift towards open-source ERP software and the need for justified investment on information security. Product quality evaluation method based on ISO 25010 framework guided the selection of attributes and factors. A security measurement framework with security posture at the highest level, attributes and factors was developed presenting a mechanism for assessing organization’s level of security. Security posture promotes customers’ confidence and gives management means to leverage resources for information security investment. The future work includes definition of metrics based on the framework.
Open-source enterprise resource planning (ERP) software has become a preferred alternative for modern organizations due to its affordable cost, availability and ease of access. Open-source software allows access to customizable code which in most instances may have security loop holes due to the nature of its releases. The study is motivated by need for accountability and security assurance by stakeholders and the need for justification of investments towards information security. The objective was to analyse security indicators for open-source resource planning software. Papers and journals published between 2017 and 2021 from IEEE, ACM, Springer, arXiv, Wiley online library and EBSCO were reviewed. Out of the publications generated through the Google search, 62 publications were selected by reading the title, abstract, introduction and full text. Results indicate un-updated software, full access rights, inadequate training, failure to comply, single authentication and unauthorized software as some of the factors that indicate open-source enterprise resource planning software security. In conclusion effectiveness of mitigation measures to address these factors shows security or insecurity. Notably, there is need to institute security control measures and metrics for the identified factors to help assess security posture of enterprises during ERP software implementation. We recommend the design of security a measurement framework and definition of a metrics suite for assessing open-source ERP software security.
scite is a Brooklyn-based organization that helps researchers better discover and understand research articles through Smart Citations–citations that display the context of the citation and describe whether the article provides supporting or contrasting evidence. scite is used by students and researchers from around the world and is funded in part by the National Science Foundation and the National Institute on Drug Abuse of the National Institutes of Health.
customersupport@researchsolutions.com
10624 S. Eastern Ave., Ste. A-614
Henderson, NV 89052, USA
This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.
Copyright © 2025 scite LLC. All rights reserved.
Made with 💙 for researchers
Part of the Research Solutions Family.